@samitouri / QOSamiQemu / commits / ce0b7a15bc

accel/mshv: Fix pointer to proc feature bitfield

Processor features are stored in a union containing two "banks": union hv_partition_processor_features { uint64_t as_uint[2]; struct { uint64_t sse3_support:1; ... } } get_proc_features() to retrieve the 2nd bank was passing a pointer that steps over the whole union (+16B) instead of picking the 2nd bank _in_ the union. This manifests in mismatching feature bits for the 2nd bank and possibly other side-effects caused by writing beyond the union. We need to step over the first bank (+8B) by using as_uint64[0/1] to correct this behaviour. Resolves: Coverity CID 1660876 Fixes: 2f6da91e8a ("accel/mshv: store partition proc features") Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com> Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com> Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com> Reviewed-by: Peter Maydell <peter.maydell@linaro.org> Message-ID: <20260701130335.418156-1-magnuskulke@linux.microsoft.com> Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

Magnus Kulke committed Jul 1, 2026 at 15:03 UTC ce0b7a15bc1f44f1d788f0a6aaa36244fa95a662
1 file changed +2 -2
accel/mshv/mshv-all.c
+2 -2
@@ -167,7 +167,7 @@ static int get_proc_features(int vm_fd,
167
168 ret = get_partition_property(vm_fd,
169 HV_PARTITION_PROPERTY_PROCESSOR_FEATURES0,
170 - features[0].as_uint64);
170 + &features->as_uint64[0]);
171 if (ret < 0) {
172 error_report("Failed to get processor features bank 0");
173 return -1;
@@ -175,7 +175,7 @@ static int get_proc_features(int vm_fd,
175
176 ret = get_partition_property(vm_fd,
177 HV_PARTITION_PROPERTY_PROCESSOR_FEATURES1,
178 - features[1].as_uint64);
178 + &features->as_uint64[1]);
179 if (ret < 0) {
180 error_report("Failed to get processor features bank 1");
181 return -1;